Логотип exploitDog
bind:CVE-2020-24388
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-24388

Количество 2

Количество 2

nvd логотип

CVE-2020-24388

больше 5 лет назад

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rfxf-4r4p-5x86

больше 3 лет назад

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-24388

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
github логотип
GHSA-rfxf-4r4p-5x86

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу